CVE-2026-68753
Awaiting Analysis Awaiting Analysis - Queue

Unauthenticated Access to Restricted Artifactory Content

Vulnerability report for CVE-2026-68753, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-28

Assigner: JFrog

Description

An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-28
Generated
2026-09-02
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jfrog artifactory 7.161.15

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an unauthenticated user to access restricted content in Artifactory if a credentialed remote repository is configured in a specific way.

Detection Guidance

Check Artifactory logs for unauthorized access attempts to restricted repositories. Review remote repository configurations for misconfigured credentialed setups. Use network monitoring tools to detect unusual outbound traffic from Artifactory servers.

Impact Analysis

An attacker could exploit this to access sensitive or proprietary data stored in Artifactory without proper authentication, potentially leading to data breaches or unauthorized access.

Compliance Impact

This vulnerability could lead to unauthorized data exposure, violating compliance requirements such as GDPR or HIPAA, which mandate strict access controls and data protection measures.

Mitigation Strategies

Review repository configurations to ensure restricted content is properly protected. Verify credentialed remote repositories are not misconfigured to expose sensitive data. Apply patches or updates from the vendor if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68753. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart